Implementing and Operating Cisco Data Center Core Technologies (DCCOR 350-601) — Free Practice Questions
10 free sample questions from a bank of 821, with the correct answers and explanations. No signup required — start practising right now.
1Refer to exhibit. Three operational endpoints are under the same application EPG. All endpoints can communicate with each other. The fabric must be configured to prevent communication between all these endpoints. Which action accomplishes this goal?
Add intra Ext-EPG contract under Web_EPG.
Set VRF policy control preference to unenforced.
Check box of forward control proxy ARP.
Configure intra EPG isolation as enforced.
Answer: D
The short version
D — Enforced intra-EPG isolation blocks same-EPG traffic. Endpoints in one EPG communicate freely by default, so isolation must be explicitly enforced.
Key concepts in this question
Endpoint Group (EPG): ACI policy object grouping endpoints with the same contract requirements.
Intra-EPG behavior: forwarding within an EPG is permitted by default without contracts.
Isolation options: setting intra-EPG isolation to enforced denies endpoint-to-endpoint traffic inside the EPG.
Why D is correct
Configuring intra EPG isolation as enforced accomplishes the goal because it programs the leaf switches to drop traffic between endpoints in the same application EPG. All three operational endpoints currently reach each other under default intra-EPG forwarding, and only the enforced isolation knob reverses that default at the EPG level without redesigning contracts or VRF policy.
Why the others are wrong
A. Intra Ext-EPG constructs govern external routed prefixes, not isolation among internal application endpoints.
B. Setting VRF policy control to unenforced affects contract enforcement scope at the VRF level, not same-EPG endpoint blocking.
C. Proxy ARP forwarding control changes ARP handling, not the data-plane permit between known endpoints.
350-601 exam tip
Default check: same EPG equals free talk — to stop it, enforce intra-EPG isolation.
2What are two requirements when planning a Cisco HyperFlex All Flash standard cluster installation using three HX240c M5 servers? (Choose Two)
If the Jumbo MTU option in the HyperFlex installer is enabled, then jumbo frames do not have to be enabled on the upstream switches.
The hypervisors must be installed to Cisco FlexFlash SD cards.
If the Jumbo MTU option in the HyperFlex installer is enabled, then jumbo frames must also be enabled on the upstream switches.
The cluster deployment type must support a mix of HDD and SSD.
The servers must be discovered, unassociated, and connected to each fabric interconnect.
Answer: C, E
The short version
C and E — Match jumbo end to end and start from clean discovered servers. Upstream switches must also carry jumbo frames, and nodes must be unassociated and reachable through both fabrics.
Key concepts in this question
Jumbo MTU: larger frames improve storage replication throughput but require consistent MTU on every hop.
Fabric interconnect discovery: servers must be factory-clean, discovered, and unassociated before HyperFlex claims them.
All Flash cluster: SSD-based capacity and caching with strict preset and network prerequisites.
Why C and E are correct
If the Jumbo MTU option in the HyperFlex installer is enabled, then jumbo frames must also be enabled on the upstream switches (C), because end-to-end MTU mismatch causes fragmentation or drops for storage traffic. The servers must be discovered, unassociated, and connected to each fabric interconnect (E), since HyperFlex builds service profiles and vNICs from unassociated hardware across redundant fabrics. Both are documented planning requirements.
Why the others are wrong
A. Claiming upstream jumbo configuration is unnecessary contradicts end-to-end MTU design; every Layer 2 hop must support the larger frame.
B. Hypervisor placement varies by design and boot policy; FlexFlash SD cards are an option, not a universal requirement for this cluster.
D. An All Flash standard cluster must use SSDs for capacity, not a mix of HDD and SSD, which describes hybrid designs.
350-601 exam tip
Plan with two checks: MTU everywhere and clean servers on both fabrics — partial jumbo or pre-associated servers fail validation.
3An engineer needs to connect Cisco UCS Fabric Interconnect (FI) to an external storage array.Due to budget limitations, the engineer must connect a Cisco UCS FI directly to an FC storage port.Which two actions must be taken to complete this connection? (Choose two.)
Configure the fabric interconnect in FC switch mode.
Set FC zoning to disabled when creating the VSAN.
Create a storage connection policy.
Configure the fabric interconnect in end-host mode.
Create the required VSAN in the SAN cloud.
Answer: A, E
The short version
A and E — Direct FC attach needs FC switch mode plus a SAN-cloud VSAN. End-host mode cannot switch native FC to a directly cabled array port.
Key concepts in this question
FC switch mode: fabric interconnect acts as a Fibre Channel switch with name services, zoning, and FLOGI.
FC end-host mode: default NPV-like behavior that uplinks to a core SAN switch, not suitable for direct array attach.
VSAN in SAN cloud: defines the isolated fabric membership for storage ports and zoning.
Why A and E are correct
Configuring the fabric interconnect in FC switch mode (A) enables native FC switching services needed when no upstream SAN switch exists, and creating the required VSAN in the SAN cloud (E) places the FI FC ports and the directly connected array ports in the same isolated fabric. Together they let the FI log in the array, enforce zoning, and present paths to service profiles under budget constraints.
Why the others are wrong
B. Disabling FC zoning removes access control rather than completing connectivity; zoning should be configured, not disabled.
C. A storage connection policy defines WWPN and target mapping for boot behavior but does not change the FI FC operating mode.
D. End-host mode uplinks to an existing SAN fabric and cannot provide direct FC switching to a storage array port.
350-601 exam tip
Direct array equals switch mode — if you see end-host mode with a direct cable, eliminate it.
4What is a disadvantage of deploying network-attached storage (NAS) versus Fibre Channel for storage?
NAS is more complex and expensive to implement.
NAS lacks the scalability and performance of Fibre Channel.
NAS centralizes storage devices, which makes them easier to manage.
NAS operates independently of an organization's operating system.
Answer: B
The short version
B — NAS trades away Fibre Channel scale and speed. File-level sharing over Ethernet cannot match dedicated lossless block fabric performance.
Key concepts in this question
NAS: file-level access over NFS or SMB on shared Ethernet, simple to deploy and share.
Fibre Channel SAN: block-level, lossless, low-latency fabric purpose-built for storage throughput and scale.
Tradeoff axis: simplicity and sharing versus deterministic performance and large-scale block provisioning.
Why B is correct
NAS lacks the scalability and performance of Fibre Channel. NAS contends with general LAN traffic, protocol overhead, and file-server head limits, while Fibre Channel provides dedicated bandwidth, lossless credit-based flow control, and massive fan-out for block workloads such as databases and virtualization. That performance and scale gap is the standard cited disadvantage of NAS.
Why the others are wrong
A. NAS is generally simpler and cheaper to implement than Fibre Channel, so complexity and cost describe FC, not NAS.
C. Centralized management ease is an advantage of NAS, not a disadvantage versus Fibre Channel.
D. Operating with broad OS compatibility is a NAS strength for file sharing, not a drawback.
350-601 exam tip
Frame it as cheap and shared versus fast and scalable — NAS wins simplicity, FC wins performance.
5An engineer needs to make an XML backup of Cisco UCS Manager. The backup should be transferred using an authenticated and encrypted tunnel and it should contain all system and service profiles configuration.Which command must be implemented to meet these requirements?
C — Use create backup over SCP with all-configuration. That syntax selects an encrypted tunnel and captures system plus service profiles.
Key concepts in this question
UCS backup types: full state, all-configuration for system plus logical config, logical, and system snapshots.
Transfer protocols: SCP and SFTP provide authenticated encrypted transport; TFTP and FTP do not.
XML backup: UCS Manager exports configuration as XML for import and disaster recovery.
Why C is correct
The command create backup scp://user@host35/backups/all-config9.bak all-configuration meets the requirements because create backup is the UCS backup verb, SCP supplies the authenticated encrypted tunnel, and the all-configuration type includes system and service profile definitions. The other verbs copy local switch configs rather than generating a UCS Manager XML backup.
Why the others are wrong
A. Create file is not the UCS Manager backup verb and does not produce the versioned XML backup object.
B. Copy startup-config targets NX-OS style local configuration and cannot emit a UCS all-configuration backup.
D. Copy running-config likewise copies the active local config, missing the authenticated backup workflow and full system scope.
350-601 exam tip
Memorize create backup plus SCP plus all-configuration — copy run or start is always the wrong verb here.
6What happens when the install all epld bootflash: m9000-pkg2-9.2.2.epld module all fan- module all bar all command is run on the Cisco MDS 9000 Series Director Switch?
The switching module starts a rolling update.
Fan modules power cycle.
The active supervisor updates first.
Each module updates and power cycles.
Answer: D
The short version
D — The all-keyword EPLD command is disruptive to every module. Each module updates and power cycles, including supervisors, switching, fan, and fabric hardware.
Key concepts in this question
EPLD: field-programmable hardware logic for supervisors, line cards, fan trays, and fabric modules.
install all epld with module all: explicitly targets every upgradable component instead of a rolling subset.
Disruption expectation: EPLD rewrites require resets, so maintenance windows are mandatory.
Why D is correct
Each module updates and power cycles when the install all epld command with module all fan-module all fabric all runs on the MDS 9000 Director. The broad all selectors program every EPLD image and then reset each hardware element to activate the new logic. That is why the operation is disruptive and must be scheduled rather than treated as a nondisruptive rolling update.
Why the others are wrong
A. A rolling switching-module-only update understates the scope; fans and fabric are also included by the command.
B. Fan modules power cycling alone is only one consequence; supervisors and line cards also reload.
C. The active supervisor updating first describes ISSU sequencing, not the blanket reset behavior of an all-module EPLD install.
350-601 exam tip
See module all plus fan plus fabric and think everything reloads — never call an all-EPLD install nondisruptive.
7Which two actions are needed to configure a single Cisco APIC controller for Cisco ACI fabric for the first time? (Choose two.)
Register the APIC that is connected to the switch.
Configure the first Cisco APIC controller
Configure the leaf switch where the Cisco APIC is connected, using CLI to allow APIC connectivity
Register the switches that are discovered through LLDP.
Register all leaf and spine switches
Answer: B, D
The short version
B and D — Configure the first APIC, then register LLDP-discovered switches. Fabric bring-up is controller-first, followed by claiming discovered nodes.
Key concepts in this question
Initial APIC setup: cluster size, fabric name, controller ID, tunnel and management addresses via console wizard.
LLDP discovery: APIC learns directly connected leaf and spine nodes through the fabric links.
Registration: discovered nodes must be registered and assigned IDs before policies push.
Why B and D are correct
Configuring the first Cisco APIC controller (B) establishes the cluster, fabric domain, and management identity that every later controller and switch joins. Registering the switches that are discovered through LLDP (D) then claims those nodes into the fabric inventory so firmware, topology, and policy can be assigned. That two-step order is the documented single-APIC bring-up flow.
Why the others are wrong
A. Registering the APIC that is connected to the switch reverses the flow; the APIC is configured first, switches are registered to it.
C. Manually configuring the leaf CLI for APIC connectivity is not required; APIC-to-switch discovery uses automatic LLDP and DHCP-based workflows.
E. Registering all leaf and spine switches overstates first bring-up; only discovered nodes are claimed, and expansion follows the same discovery process.
350-601 exam tip
Order matters: APIC first, discovered switches second — CLI leaf config is the distractor.
8What is the advantage of using the NFS protocol versus the iSCSI or FCoE SAN protocols?
NFS is more sensitive to latency.
NFS provides easy file sharing.
NFS natively provides encryption as the default.
NFS requires an AAA server.
Answer: B
The short version
B — NFS wins on simple file sharing. iSCSI and FCoE deliver block LUNs, while NFS natively shares files across clients.
Key concepts in this question
NFS: network file-system protocol exporting hierarchical shares to many clients at once.
iSCSI and FCoE: block transports presenting raw LUNs that each host must format with its own filesystem.
Sharing model: file sharing versus block assignment determines administrative overhead.
Why B is correct
NFS provides easy file sharing because multiple hosts can mount the same export concurrently with centralized permissions and locking handled at the file level. iSCSI and FCoE instead dedicate block volumes to initiators, so sharing one volume safely requires clustered filesystems or extra coordination. For straightforward multi-client document and VM datastores, NFS simplicity is the cited advantage.
Why the others are wrong
A. Greater sensitivity to latency is a drawback of NFS, not an advantage over tuned block SANs.
C. NFS does not natively provide encryption by default; secure variants and helpers add it, but it is not the headline advantage.
D. NFS does not require an AAA server; it can integrate with directory services, but that is not its differentiator.
350-601 exam tip
Think files equal shared and blocks equal dedicated — NFS is the easy-share answer.
9Refer to the exhibit. A user must be granted management access to the Cisco Nexus 9000 Series Switch using AAA servers. The RADIUS servers are configured to accept login requests from the same Layer 2 subnet of the switch. The user must be permitted to log in with these requirements:- RADIUS server 1 must be used to log in via a console.- RADIUS server 2 must be used to login via SSH.Which two actions meet these requirements? (Choose two.)
Configure the authentication login to use group RAD1 for console and group RAD2 for remote access.
Set the RADIUS source interface to be mgmt0 for group RAD1 and VLAN 22 for group RAD2.
Change the dead timer for RAD1 and RAD2 to 1 minute.
Configure AAA to send the accounting traffic to RAD1 and RAD2.
Enable command authorization to RAD1 and RAD2 for all successful logins.
Answer: A, B
The short version
A and B — Split login by group and source from the right interfaces. Console uses RAD1 and SSH uses RAD2, each sourced from its own Layer 2-adjacent address.
Key concepts in this question
AAA login separation: console and default or remote logins can reference different server groups.
RADIUS source interface: determines the source IP the switch presents, which must sit in the servers accepted subnet.
Nexus groups: named server groups such as RAD1 and RAD2 map to distinct server sets.
Why A and B are correct
Configuring authentication login to use group RAD1 for console and group RAD2 for remote access (A) enforces the required server split for console versus SSH logins. Setting the RADIUS source interface to mgmt0 for RAD1 and VLAN 22 for RAD2 (B) ensures each request arrives from an address on the same Layer 2 subnet the servers accept. Together they satisfy both the login-path and reachability requirements.
Why the others are wrong
C. Changing the dead timer tunes failover timing but does not steer console versus SSH to different servers.
D. AAA accounting sends usage records and does not select which server authenticates each login method.
E. Command authorization controls post-login privilege, not the initial console-versus-SSH server choice or source addressing.
350-601 exam tip
Two knobs for split login: aaa group per login type plus source-interface per group — timers and accounting never split paths.
10Which NFS version uses the TCP protocol and needs only one IP port to run the service?
NFSv1
NFSv2
NFSv3
NFSv4
Answer: D
The short version
D — NFSv4 runs on TCP port 2049 only. Earlier versions needed multiple RPC ports plus portmapper services.
Key concepts in this question
NFSv2 and NFSv3: rely on UDP or TCP plus auxiliary mount, lock, and status daemons on separate ports.
NFSv4: consolidates everything onto well-known TCP port 2049 with integrated locking and stronger security.
Firewall benefit: a single port simplifies filtering and NAT traversal.
Why D is correct
NFSv4 uses the TCP protocol and needs only one IP port to run the service. By collapsing mount, locking, and data access into TCP 2049, it removes the portmapper and sideband RPC services that NFSv2 and NFSv3 required. That single-port TCP design is the version feature the question asks for.
Why the others are wrong
A. NFSv1 was an internal experimental version and never defined the consolidated TCP service.
B. NFSv2 uses UDP with multiple RPC services and portmapper lookups, not a single TCP port.
C. NFSv3 still depends on separate auxiliary protocols for mount and locking across multiple ports.
350-601 exam tip
Remember 4 equals four letters in one port — NFSv4_fi Single TCP 2049.